Vulnerability CVE-2014-8178


Published: 2019-12-17

Description:
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.9/10
2.9/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Opensuse -> Opensuse 
Docker -> Cs engine 
Docker -> Docker 

 References:
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00014.html
http://lists.opensuse.org/opensuse-updates/2015-10/msg00036.html
https://github.com/docker/docker/blob/master/CHANGELOG.md#183-2015-10-12
https://groups.google.com/forum/#!msg/docker-dev/bWVVtLNbFy8/UaefOqMOCAAJ
https://www.docker.com/legal/docker-cve-database

Copyright 2024, cxsecurity.com

 

Back to Top